The proliferation of AI coding assistants has created a new, often overlooked attack surface: the local conversation history. On October 2, 2026, a developer known as 'thesubtlety' released Agent Scrub, a macOS utility designed to find and redact API keys, tokens, and other secrets stored in plaintext within the transcript files of tools like Claude Code, Cursor, and Codex. While developers are accustomed to protecting their .env files, few realize that the very tools meant to accelerate development are logging sensitive credentials into persistent history files on the local machine.
The Invisible Attack Surface
Modern AI agents store prompts, transcripts, tool outputs, and saved memory locally to maintain context. Agent Scrub specifically targets these conversation-related files, distinguishing them from active credential stores like auth.json or config.yaml. The tool’s logic is precise: it removes the redundant, leaked copies of secrets found in chat history without touching the active credentials the tool uses for authentication. This separation ensures that scrubbing a transcript does not break the agent’s ability to connect to its backend services, a critical distinction for maintaining workflow stability.
Local-First Security Architecture
Privacy purists will appreciate that Agent Scrub operates entirely offline. The application makes no network connections; all scanning, state management, and redaction occur locally on the user’s Mac. To handle the sensitive nature of the detected secrets, the tool generates a random per-install key stored in the macOS Keychain. This key fingerprints detected secrets, allowing the application’s database to track findings without storing the actual secret values in plaintext. The tool supports a wide range of agents, including Gemini CLI, GitHub Copilot, Windsurf, Cody, Cline, Aider, and Continue, covering the majority of the current AI-assisted development landscape.
Operational Mechanics and Limitations
Agent Scrub runs as a menu bar application, scanning on launch and monitoring supported history locations for changes. It offers granular control, allowing users to reveal secrets, decode JWTs, or redact them in place. Redaction replaces the sensitive data with a [REDACTED:…] marker. However, users must be aware of the tool’s limitations: it can only remove local copies. If a secret has already been sent to a provider or copied into a backup, Agent Scrub cannot retrieve it. Additionally, redaction modifies original history files and cannot be automatically undone, requiring careful review before committing to the changes.
Key Takeaways
- Agent Scrub scans local conversation history for Claude, Cursor, Codex, and other major AI coding agents to find plaintext secrets.
- The tool operates entirely offline, using macOS Keychain for fingerprinting to avoid storing secret values in plaintext.
- Redaction is destructive and irreversible by default, targeting only transcript copies while leaving active credential files untouched.
- Requires macOS 14 or later and currently supports both Apple Silicon and Intel architectures via universal builds.
The Bottom Line
We have been so focused on securing the cloud that we forgot our local machines are leaking data through the very tools we use to build software. Agent Scrub is a necessary band-aid for an ecosystem that prioritizes convenience over hygiene, but it’s a stark reminder that your chat history is a database you don’t control.
Hacker’s Corner
For those running Linux or Windows, Agent Scrub is currently macOS-only, leaving a significant gap in the market. The command-line interface hgctl offers dry-run capabilities for write operations, which is a smart design choice for cautious admins. If you’re already using geiger to check credential access, pairing it with a scrubber like this closes the loop on local exposure. The open-source nature of the project is its strongest asset—audit the code, because you’re trusting it to touch your most sensitive files.